PatchSiren

SciPhi-AI CVE debriefs

These pages are published after PatchSiren validates generated defensive summaries against stored public CVE and source evidence.

HIGH SciPhi-AI CVE published 2026-08-28

CVE-2026-82271

CVE-2026-82271 is a high-severity vulnerability in R2R versions up to 3.6.5. The issue allows authenticated users to modify conversations belonging to other users due to improper validation of user ownership in conversation update and message handlers. Attackers can manipulate conversation identifiers to rename conversations and append messages to other users' histories, potentially corrupting state and i [truncated]